chore: update api middlewares

pull/2236/head
Steven 1 year ago
parent 3a1f82effa
commit d5c1706e9c

@ -67,19 +67,26 @@ func NewServer(ctx context.Context, profile *profile.Profile, store *store.Store
e.Use(middleware.CORS()) e.Use(middleware.CORS())
e.Use(middleware.SecureWithConfig(middleware.SecureConfig{
Skipper: defaultGetRequestSkipper,
XSSProtection: "1; mode=block",
ContentTypeNosniff: "nosniff",
XFrameOptions: "SAMEORIGIN",
HSTSPreloadEnabled: false,
}))
e.Use(middleware.TimeoutWithConfig(middleware.TimeoutConfig{ e.Use(middleware.TimeoutWithConfig(middleware.TimeoutConfig{
ErrorMessage: "Request timeout",
Timeout: 30 * time.Second, Timeout: 30 * time.Second,
})) }))
e.Use(middleware.RateLimiterWithConfig(middleware.RateLimiterConfig{
Store: middleware.NewRateLimiterMemoryStoreWithConfig(
middleware.RateLimiterMemoryStoreConfig{Rate: 30, Burst: 60, ExpiresIn: 3 * time.Minute},
),
IdentifierExtractor: func(ctx echo.Context) (string, error) {
id := ctx.RealIP()
return id, nil
},
ErrorHandler: func(context echo.Context, err error) error {
return context.JSON(http.StatusForbidden, nil)
},
DenyHandler: func(context echo.Context, identifier string, err error) error {
return context.JSON(http.StatusTooManyRequests, nil)
},
}))
serverID, err := s.getSystemServerID(ctx) serverID, err := s.getSystemServerID(ctx)
if err != nil { if err != nil {
return nil, fmt.Errorf("failed to retrieve system server ID: %w", err) return nil, fmt.Errorf("failed to retrieve system server ID: %w", err)

Loading…
Cancel
Save